CVE-2026-50226
AES-128-CBC Key Forgery in AcerConnect OTA
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: 8fc372e3-d9c5-46e4-9410-38469745c639
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| acer | acerconnect | *-* |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves fixed AES-128-CBC encryption keys embedded within the AcerConnect OTA application. Because these keys are fixed and predictable, attackers can forge authorization credentials for any IMEI number. This unauthorized access enables attackers to list catalog items and extract protected binary files from pre-signed cloud links.
How can this vulnerability impact me? :
The vulnerability allows unauthorized actors to gain access to protected content by forging authorization credentials. This can lead to exposure of sensitive binaries and catalog information that should be restricted, potentially compromising device security and intellectual property.